Hi,
I'm trying to test the ability to "Configuring Multiple LDAP Servers". Actually, I want to connect to the same LDAP server but with a different base_dn and priority for each authentication entry. (I have a client that has user in different OUs in the same tree,)
I created two LDAP authentication methods like this:
DROP AUTHENTICATION vldap1 CASCADE; CREATE AUTHENTICATION vldap1 METHOD 'ldap' LOCAL; GRANT AUTHENTICATION vldap1 TO public; ALTER AUTHENTICATION vldap1 SET host='ldap://xx.xx.xx.xx/', basedn='ou=verticausers,dc=mydomain,dc=com', binddn='cn=root,dc=mydomain,dc=com', bind_password='xxxx'; ALTER AUTHENTICATION vldap1 PRIORITY 1; DROP AUTHENTICATION vldap2 CASCADE; CREATE AUTHENTICATION vldap2 METHOD 'ldap' LOCAL; GRANT AUTHENTICATION vldap2 TO public; ALTER AUTHENTICATION vldap2 SET host='ldap://xx.xx.xx.xx/', basedn='cn=admin,ou=organizationalUnit,dc=mydomain,dc=com', binddn='cn=root,dc=mydommain,dc=com', bind_password='1234'; ALTER AUTHENTICATION vldap2 PRIORITY 0;
I have 2 users defined in LDAP:
Distinguished Name: cn= blank_admin,cn=admin,ou=organizationalUnit,dc=mydomain,dc=com
Distinguished Name: cn= blank,cn=generic,ou=verticausers,dc=mydomain,dc=com
Here they are in Vertica:
dbadmin=> select * from user_client_auth where user_name in ('blank', 'blank_admin');
user_oid | user_name | auth_oid | auth_name | granted_to
-------------------+-------------+-------------------+-----------+------------
45035996274640894 | blank | 45035996274647600 | vldap1 | public
45035996274640894 | blank | 45035996274647604 | vldap2 | public
45035996274641936 | blank_admin | 45035996274647600 | vldap1 | public
45035996274641936 | blank_admin | 45035996274647604 | vldap2 | public
(4 rows)
When I try to log in as the user blank, it works fine:
[dbadmin@localhost ~]$ vsql -U blank -w test123 -c "select client_authentication_name from sessions;" client_authentication_name ---------------------------- vldap1 (1 row)
But logging in as blank_admin fails:
[dbadmin@localhost ~]$ vsql -U blank_admin -w test123 -c "select client_authentication_name from sessions;" vsql: FATAL 3846: LDAP authentication failed for user "blank_admin"
I was hoping that it would use the vldap2 authentication method...
So, when I drop the vldap1 authentication method, I can then log in as the blank_admin user:
[dbadmin@localhost ~]$ vsql -c "drop authentication vldap1 cascade;" DROP AUTHENTICATION [dbadmin@localhost ~]$ vsql -U blank_admin -w test123 -c "select client_authentication_name from sessions;" client_authentication_name ---------------------------- vldap2 (1 row)
So, the question is, why does this not work when vldap1 exists? Why does Vertica not continue on to vldap2 when it fails on vldap1?
Thanks!
